
Exploitation toolkit for RichFaces
Richsploit: RichFaces के लिए शोषण टूलकिट।
अवलोकन
Richsploit का उपयोग RichFaces का उपयोग करके JSF एंडपॉइंट्स का शोषण करने के लिए किया जा सकता है। 3.1.0 और उससे ऊपर के सभी संस्करण असुरक्षित हैं।
usage: Richsploit
-e,--exploit 0: CVE-2013-2165
1: CVE-2015-0279
2: CVE-2018-12532
3: CVE-2018-12533
4: CVE-2018-14667
-p,--payload The file containing serialized object
(CVE-2013-2165), or
Shell command to execute (all other CVE's)
-u,--url URL of richfaces application, i.e.
http://example.com/app for RF4.x and
http://example.com/app/a4j/g/3_3_3.Final for RF3.x
-v,--version Richfaces branch, either 3 or 4
टूल का उपयोग करने के तरीके के बारे में अधिक जानकारी के लिए, कृपया यह ब्लॉग पोस्ट देखें।